cbcvebase.
CVE-2021-1578
published 2021-08-25

CVE-2021-1578: A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller…

PriorityP259high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.97%
78.3th percentile
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected device. This vulnerability is due to an improper policy default setting. An attacker could exploit this vulnerability by using a non-privileged credential for Cisco ACI Multi-Site Orchestrator (MSO) to send a specific API request to a managed Cisco APIC or Cloud APIC device. A successful exploit could allow the attacker to obtain Administrator credentials on the affected device.

Affected

6 ranges
VendorProductVersion rangeFixed in
ciscoapplication_policy_infrastructure_controller
ciscoapplication_policy_infrastructure_controller
ciscoapplication_policy_infrastructure_controller5.0 – 5.1\(3e\)
ciscocisco_application_policy_infrastructure_controller
ciscocloud_application_policy_infrastructure_controller
ciscocloud_application_policy_infrastructure_controller5.0 – 5.1\(3e\)

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for non-privileged MSO credential usage sending API requests to APIC or Cloud APIC devices that result in Administrator-level privilege escalation
  • Alert on any API responses from APIC/Cloud APIC that return or grant Administrator credentials to sessions that originated from non-privileged MSO accounts
  • ·The vulnerability is caused by an improper policy default setting on APIC/Cloud APIC; review and harden default API endpoint policies to restrict privilege escalation paths from MSO-sourced requests
  • ·There are no workarounds available; patching via Cisco software updates is the only remediation (tracked under Bug ID CSCvw57550)

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.